Back to skill

Security audit

Zoom

Security checks for vulnerabilities and agentic risk

Overview

This Zoom skill appears legitimate, but should be reviewed because it installs a persistent third-party plugin that handles Zoom OAuth and exposes broad read/write Zoom capabilities.

Install only if you trust ClawLink with your Zoom account connection. Before authorizing, review the Zoom scopes, use preview and explicit confirmation for every create/update/delete/register action, and know how to revoke the Zoom connection and remove the plugin if needed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:47
Finding

Unpinned Third-Party Plugin Handles Sensitive Zoom OAuth Data

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:33, 47-49, 71, 77
Vulnerability Type: Unpinned third-party dependency with access to OAuth tokens and proxied Zoom data
Risk Level: Medium

Relevant code snippets:

text
           │                       │  5. Proxy Requests    │
bash
openclaw plugins install clawhub:clawlink-plugin
openclaw config set tools.alsoAllow '["clawlink-plugin"]' --strict-json
openclaw gateway restart
text
**No API key is required in chat.** ClawLink stores the OAuth token securely and injects it into every Zoom API request on the user's behalf.
text
3. Open https://claw-link.dev/dashboard?add=zoom and connect Zoom.

Technical Analysis

The Skill directs users to install clawhub:clawlink-plugin without pinning an immutable version or artifact digest. It then adds the plugin to the OpenClaw tool allowlist and restarts the gateway. The installed component is therefore trusted to operate as an enabled plugin, while the package contents resolved by the installation command may change independently of this audited Skill file.

The documented architecture also delegates Zoom OAuth-token storage and API-request proxying to ClawLink. This places sensitive credentials and Zoom account data across an external trust boundary. Although the document claims that tokens are stored securely, the audited project contains no implementation with which to verify token handling, retention, isolation, or transport controls.

This is a supply-chain weakness rather than evidence that the current plugin or ClawLink service is malicious. The risk arises because a later compromised or replaced plugin release could be installed under the same unpinned identifier and then process credentials and data after being explicitly enabled.

Attack Path

  1. An attacker compromises the plugin publisher, package registry entry, release pipeline, or artifact-delivery chan ...[truncated 1587 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin clawlink-plugin to a reviewed immutable version rather than installing an unconstrained package identifier.
  2. Verify the package with a publisher signature, cryptographic digest, provenance attestation, or equivalent integrity mechanism before installation.
  3. Document the expected plugin version, publisher identity, source repository, review status, and upgrade process.
  4. Require explicit user approval before installing the plugin, changing the tool allowlist, restarting the gateway, pairing a device, or expanding OAuth scopes.
  5. Display the exact Zoom OAuth scopes before authorization and request only those required for the user's requested operation.
  6. Separate read-only capabilities from write and destructive capabilities, granting write scopes only when necessary.
  7. Document what credentials and Zoom data pass through ClawLink, where they are stored, how long they are retained, and how users can revoke and delete them.
  8. Use short-lived credentials, encrypted storage and transport, tenant isolation, access logging, token rotation, and immediate revocation controls.
  9. Prefer direct Zoom OAuth and user-controlled token storage where practical, reducing reliance on an external credential proxy.
  10. Re-audit each plugin upgrade before deployment and monitor for unexpected changes to plugin permissions, network destinations, and tool behavior.
Vulnerability Patterns
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill metadata and description scope the integration to meetings, webinars, registrants, recordings, and event workflows, but the documented tool reference also exposes Zoom Revenue Accelerator conversation tools. That mismatch can mislead users and higher-level policy layers about what data and actions are in scope, potentially enabling access to sensitive sales/conversation intelligence data that users did not expect this skill to handle.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The skill repeatedly states that all write operations require explicit confirmation and a preview step, but the code examples show direct invocation of write tools. In agent settings where examples are copied or treated as normative behavior, this inconsistency can bypass intended human confirmation safeguards and lead to unintended meeting creation or registrant changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.